This is a guest blog post written by Aatika Al-Hinai, Mais Al-Hajri, Malak Al-Kharusi, and Mohammed Al-Lawati as part of their Decree Fellowship group project in July 2026.
The Personal Data Protection Law (Royal Decree No. 6/2022) has been in force since February 2023. It is Oman’s first comprehensive data protection statute, and a clear step forward from the single chapter of the Electronic Transactions Law that previously governed the field. Across its 32 articles, the PDPL grants data subjects a genuine set of rights and places clear obligations on controllers, giving the Sultanate a solid foundation to build on.
This policy brief examines that framework through the lens of data subject rights and identifies three areas where targeted refinement would strengthen it. First, the right of access could be broadened so that a copy of one’s data comes with the context needed to judge how it is being used. Second, a limited set of lawful bases could sit alongside consent, freeing consent to do its real work of protecting higher-risk processing. Third, a personal route to compensation could run alongside the Ministry’s enforcement role. Drawing on comparators including the UK GDPR and the Saudi and UAE frameworks, each reform builds on what the PDPL already does rather than reworking it.